The basics of Penetration Testing, Enumeration, Privilege Escalation and WebApp testing
No need
After enumerating the services and resources available on this machine, what did you discover?
Node.js
31331
Apache
Ubuntu
The software using the port 8081 is a REST api, how many of its routes are used by the web application?
2
Now that you know which services are available, it's time to exploit them!
Did you find somewhere you could try to login? Great!
Quick and dirty login implementations usually goes with poor data management.
There must be something you can do to explore this machine more thoroughly..
utech.db.sqlite
f357a0c52799563c7c7b76c1e7543a32
n100906
Congrats if you've made it this far, you should be able to comfortably run commands on the server by now!
Now's the time for the final step!
You'll be on your own for this one, there is only one question and there might be more than a single way to reach your goal.
Mistakes were made, take advantage of it.
MIIEogIBA
